From owner-freebsd-security@FreeBSD.ORG Sun May 8 07:52:10 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id C4A27106564A for ; Sun, 8 May 2011 07:52:10 +0000 (UTC) (envelope-from jhellenthal@gmail.com) Received: from mail-iy0-f182.google.com (mail-iy0-f182.google.com [209.85.210.182]) by mx1.freebsd.org (Postfix) with ESMTP id 7964B8FC12 for ; Sun, 8 May 2011 07:52:10 +0000 (UTC) Received: by iyj12 with SMTP id 12so5172768iyj.13 for ; Sun, 08 May 2011 00:52:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:sender:date:from:to:cc:subject:message-id :references:mime-version:content-type:content-disposition :in-reply-to:x-openpgp-key-id:x-openpgp-key-fingerprint :x-openpgp-key-url; bh=9rn0AOmLnOTkmZ01qZ/wIJy2pzN+mQopEdhmsF2oSiI=; b=PJI6CWeIRXmRyXD5YYBTIjBG14+6hCsbtOc8s27+lr+5IPlSAKSMNcfus8UvPvqIZ/ 5ctMrkwuHbsGRpodQvn/sM0jfne30WTZzDxQ8q4f8s/Jst4AF/EOuFUvxNL502ErW2af hDtn/gACyyC6MWxVCwlLASPy/zUxhKeJqd2KQ= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=sender:date:from:to:cc:subject:message-id:references:mime-version :content-type:content-disposition:in-reply-to:x-openpgp-key-id :x-openpgp-key-fingerprint:x-openpgp-key-url; b=Mzn5vuzzUsONKcuOb65Zt04sNBEMcbXVKD/WzbbHo1aNDRQ1PyF9z5qm7lC3tLd86N SUogGu0KBY+AcjM9g+q4as6E/7bluDooj8cPfxNC43oBRGZfRpFAhd4HYfHMKzp6D8Dh GuxOTYcTZzaCBYeuxgl5F2Sa0PwvIvapHsdoY= Received: by 10.42.168.9 with SMTP id u9mr2783332icy.214.1304841129083; Sun, 08 May 2011 00:52:09 -0700 (PDT) Received: from DataIX.net (adsl-99-190-84-116.dsl.klmzmi.sbcglobal.net [99.190.84.116]) by mx.google.com with ESMTPS id y10sm2098825iba.12.2011.05.08.00.52.07 (version=TLSv1/SSLv3 cipher=OTHER); Sun, 08 May 2011 00:52:08 -0700 (PDT) Sender: "J. Hellenthal" Received: from DataIX.net (localhost [127.0.0.1]) by DataIX.net (8.14.4/8.14.4) with ESMTP id p487q4RC067017 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 8 May 2011 03:52:05 -0400 (EDT) (envelope-from jhell@DataIX.net) Received: (from jhell@localhost) by DataIX.net (8.14.4/8.14.4/Submit) id p487q3VI067016; Sun, 8 May 2011 03:52:03 -0400 (EDT) (envelope-from jhell@DataIX.net) Date: Sun, 8 May 2011 03:52:03 -0400 From: Jason Hellenthal To: Edho P Arief Message-ID: <20110508075203.GA61754@DataIX.net> References: <4DC40E21.6040503@gmail.com> <4DC4102E.8000700@gmail.com> <201105072231.p47MVktY035491@catflap.bishopston.net> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="8t9RHnE3ZwKMSgU+" Content-Disposition: inline In-Reply-To: X-OpenPGP-Key-Id: 0x89D8547E X-OpenPGP-Key-Fingerprint: 85EF E26B 07BB 3777 76BE B12A 9057 8789 89D8 547E X-OpenPGP-Key-URL: http://bit.ly/0x89D8547E Cc: Jamie Landeg Jones , freebsd-security@freebsd.org, feld@feld.me, utisoft@gmail.com Subject: Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 08 May 2011 07:52:10 -0000 --8t9RHnE3ZwKMSgU+ Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Edho, On Sun, May 08, 2011 at 09:15:28AM +0700, Edho P Arief wrote: > On Sun, May 8, 2011 at 5:31 AM, Jamie Landeg Jones = wrote: > >> All the same, I've sent a PR [1] with some doc patches to make people > >> more aware of this -- fulfilling my promise of 2+ years ago :S > >> > >> Thanks! > >> > >> Chris > >> > >> [1] http://www.freebsd.org/cgi/query-pr.cgi?pr=3D156853 > > > > Um. Some problems here. > > > > A jail won't work for not-root users if the jail root directory is chmo= d 700 - although > > there is obviously a 'chroot' running withing the jail, the jailed user= still needs > > to have read permission from the hosts / -- chmod 700 therefore locks a= ll non-root > > users out. > > >=20 > It's weird - I don't remember having such problem after setting jails' > root directory permission to 700. I don't have the system anymore so I > can't verify it just yet. It should also be noted here that the jailed root user also has permission= =20 to chmod(1) '/' to anything he or she wants unless you have taken=20 precaution to not allow that. I would reccoment storing your jails two=20 levels deep into a directory and chmod(1) 700 the first level to prevent=20 access from the host and from the jailed root user changing the perms. --=20 Regards, (jhell) Jason Hellenthal --8t9RHnE3ZwKMSgU+ Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.17 (FreeBSD) Comment: http://bit.ly/0x89D8547E iQEcBAEBAgAGBQJNxkuiAAoJEJBXh4mJ2FR+/1wH/2jhRwdIdWNWL4znJnN0j2H7 eOEeCZHzs80S1v4lEug+6Ka/XLU0ag4N1dDCOkU3FzP5tptM9pCx6LHjsJa57pkv nJZWAz5e9khRKzv3F55wYBHlY5sD9zb64Tf2NpeTLvT+T4C3MvLY3ju2jVlShQcN ZsFeSyvMb2t/t7ADWP4x/fyWvQDs05edPyDMR3ipKUeje5DIV5tL/DAVg0cBefix 3PINhW17rxXrWsvyxwTrshtHfwYLzuUoF0Lnj7KUKw1gE7n7H5eobmllMvvzZZ/7 lmrRCjdWiMLTdKgqPxPMSX5lzjwnCoaYVC/+Lw4o5sWL4/lqYD81vLXzx+6OFA0= =ZjGb -----END PGP SIGNATURE----- --8t9RHnE3ZwKMSgU+--